{"api_version":"1","generated_at":"2026-09-08T02:52:55+00:00","cve":"CVE-2026-64045","urls":{"html":"https://cve.report/CVE-2026-64045","api":"https://cve.report/api/cve/CVE-2026-64045.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64045","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64045"},"summary":{"title":"ovpn: tcp - use cached peer pointer in ovpn_tcp_close()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\novpn: tcp - use cached peer pointer in ovpn_tcp_close()\n\novpn_tcp_close() loads the ovpn_socket via rcu_dereference_sk_user_data()\nunder rcu_read_lock(), takes a reference on sock->peer, caches the peer\npointer in a local, and drops the read lock. It then passes sock->peer\n(rather than the cached local) to ovpn_peer_del(), re-dereferencing the\novpn_socket after the RCU read section has ended.\n\nUnlike ovpn_tcp_sendmsg(), which uses the same \"load under RCU, use\nafter unlock\" pattern but is protected by lock_sock() held across the\nfunction, ovpn_tcp_close() runs without the socket lock: inet_release()\ninvokes sk_prot->close() without taking lock_sock first.\n\novpn_socket_release() can therefore complete its kref_put -> detach ->\nsynchronize_rcu -> kfree(sock) sequence concurrently, in the window\nafter ovpn_tcp_close() drops rcu_read_lock() but before it dereferences\nsock->peer. The synchronize_rcu() in ovpn_socket_release() protects\nreaders that use the dereferenced pointer inside the RCU read section,\nnot those that escape the pointer to a local and use it afterwards.\n\nA reproducer follows the pattern of commit 94560267d6c4 (\"ovpn: tcp -\ndon't deref NULL sk_socket member after tcp_close()\"): trigger a peer\nremoval (keepalive expiration or netlink OVPN_CMD_DEL_PEER) at the same\nmoment userspace closes the TCP fd. That commit fixed the detach-side\nof the same race window; this one fixes the close-side at a different\nvictim.\n\nTighten the entry block to read sock->peer exactly once into the cached\npeer local, and route all subsequent uses (the hold check, the\novpn_peer_del() call, and the prot->close() invocation) through that\nlocal. sock->peer is only ever written once in ovpn_socket_new() under\nlock_sock(), before rcu_assign_sk_user_data() publishes the ovpn_socket,\nand is never reassigned afterwards - but the previous multi-read pattern\nmade that invariant implicit rather than explicit. The same multi-read\nshape exists in ovpn_tcp_recvmsg(), ovpn_tcp_sendmsg(),\novpn_tcp_data_ready() and ovpn_tcp_write_space(); those will be cleaned\nup via a dedicated helper in a follow-up net-next series.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:44","updated_at":"2026-09-02 21:11:22"},"problem_types":["CWE-476"],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/d3ef441907fca7c340979e577a3db3bb634bf166","name":"https://git.kernel.org/stable/c/d3ef441907fca7c340979e577a3db3bb634bf166","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e5460eb7238c19d651a9b22b2378b587033a4095","name":"https://git.kernel.org/stable/c/e5460eb7238c19d651a9b22b2378b587033a4095","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/775d8d7ad02aa345e1588424a6a8b9ae49fb9012","name":"https://git.kernel.org/stable/c/775d8d7ad02aa345e1588424a6a8b9ae49fb9012","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64045","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64045","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 11851cbd60ea1e5abbd97619d69845ead99303d6 e5460eb7238c19d651a9b22b2378b587033a4095 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 11851cbd60ea1e5abbd97619d69845ead99303d6 d3ef441907fca7c340979e577a3db3bb634bf166 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 11851cbd60ea1e5abbd97619d69845ead99303d6 775d8d7ad02aa345e1588424a6a8b9ae49fb9012 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.34 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.11 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"64045","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64045","cve":"CVE-2026-64045","epss":"0.001540000","percentile":"0.050320000","score_date":"2026-08-02","updated_at":"2026-08-03 00:14:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/ovpn/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"e5460eb7238c19d651a9b22b2378b587033a4095","status":"affected","version":"11851cbd60ea1e5abbd97619d69845ead99303d6","versionType":"git"},{"lessThan":"d3ef441907fca7c340979e577a3db3bb634bf166","status":"affected","version":"11851cbd60ea1e5abbd97619d69845ead99303d6","versionType":"git"},{"lessThan":"775d8d7ad02aa345e1588424a6a8b9ae49fb9012","status":"affected","version":"11851cbd60ea1e5abbd97619d69845ead99303d6","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/ovpn/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.16"},{"lessThan":"6.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.34","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.34","versionStartIncluding":"6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.11","versionStartIncluding":"6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"6.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\novpn: tcp - use cached peer pointer in ovpn_tcp_close()\n\novpn_tcp_close() loads the ovpn_socket via rcu_dereference_sk_user_data()\nunder rcu_read_lock(), takes a reference on sock->peer, caches the peer\npointer in a local, and drops the read lock. It then passes sock->peer\n(rather than the cached local) to ovpn_peer_del(), re-dereferencing the\novpn_socket after the RCU read section has ended.\n\nUnlike ovpn_tcp_sendmsg(), which uses the same \"load under RCU, use\nafter unlock\" pattern but is protected by lock_sock() held across the\nfunction, ovpn_tcp_close() runs without the socket lock: inet_release()\ninvokes sk_prot->close() without taking lock_sock first.\n\novpn_socket_release() can therefore complete its kref_put -> detach ->\nsynchronize_rcu -> kfree(sock) sequence concurrently, in the window\nafter ovpn_tcp_close() drops rcu_read_lock() but before it dereferences\nsock->peer. The synchronize_rcu() in ovpn_socket_release() protects\nreaders that use the dereferenced pointer inside the RCU read section,\nnot those that escape the pointer to a local and use it afterwards.\n\nA reproducer follows the pattern of commit 94560267d6c4 (\"ovpn: tcp -\ndon't deref NULL sk_socket member after tcp_close()\"): trigger a peer\nremoval (keepalive expiration or netlink OVPN_CMD_DEL_PEER) at the same\nmoment userspace closes the TCP fd. That commit fixed the detach-side\nof the same race window; this one fixes the close-side at a different\nvictim.\n\nTighten the entry block to read sock->peer exactly once into the cached\npeer local, and route all subsequent uses (the hold check, the\novpn_peer_del() call, and the prot->close() invocation) through that\nlocal. sock->peer is only ever written once in ovpn_socket_new() under\nlock_sock(), before rcu_assign_sk_user_data() publishes the ovpn_socket,\nand is never reassigned afterwards - but the previous multi-read pattern\nmade that invariant implicit rather than explicit. The same multi-read\nshape exists in ovpn_tcp_recvmsg(), ovpn_tcp_sendmsg(),\novpn_tcp_data_ready() and ovpn_tcp_write_space(); those will be cleaned\nup via a dedicated helper in a follow-up net-next series."}],"metrics":[{"cvssV3_1":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code runs only in ovpn_tcp_close(), reached via the close() syscall path (inet_release() -> sk_prot->close) on a TCP socket attached to the ovpn driver. Remote network packets do not directly invoke this function.\nAC:L - The reproducer is a race between closing the TCP fd and concurrent peer removal (keepalive expiry or OVPN_CMD_DEL_PEER). The attacker controls both sides by timing close() against peer deletion, and can retry until the window is hit.\nPR:N - On an internet-facing OpenVPN server with kernel TCP offload, a remote VPN peer needs no Linux credentials: stopping traffic triggers kernel keepalive expiry and ovpn_socket_release(), while the local daemon concurrently closes the TCP socket as part of normal teardown.\nUI:N - Exploitation does not require any victim user action beyond normal automated VPN server operation reacting to peer timeout or disconnect.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the host kernel; it does not cross a VM, container, or IOMMU security boundary.\nC:H - This is a use-after-free: after RCU ends, ovpn_tcp_close() re-dereferences sock->peer on a freed ovpn_socket, enabling reads of attacker-influenced freed heap contents and potential information disclosure.\nI:H - The stale sock->peer pointer is passed to ovpn_peer_del(), which operates on peer structures and locks; corrupted pointers can cause arbitrary kernel memory corruption exploitable for control-flow hijacking.\nA:H - The UAF can cause kernel oops/panic during peer deletion or TCP close, and use-after-free on kmalloc objects routinely causes system crashes even when not fully weaponized."}]}],"providerMetadata":{"dateUpdated":"2026-08-05T12:38:37.111Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/e5460eb7238c19d651a9b22b2378b587033a4095"},{"url":"https://git.kernel.org/stable/c/d3ef441907fca7c340979e577a3db3bb634bf166"},{"url":"https://git.kernel.org/stable/c/775d8d7ad02aa345e1588424a6a8b9ae49fb9012"}],"title":"ovpn: tcp - use cached peer pointer in ovpn_tcp_close()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64045","datePublished":"2026-07-19T15:39:30.526Z","dateReserved":"2026-07-19T07:54:57.029Z","dateUpdated":"2026-08-05T12:38:37.111Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:44","lastModifiedDate":"2026-09-02 21:11:22","problem_types":["CWE-476"],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"6.18.34","matchCriteriaId":"2437F48D-051C-4E78-83C2-F198D0F2AE92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.0.11","matchCriteriaId":"0520D091-FC52-4A50-AF07-70AE7D08B750"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*","matchCriteriaId":"B1EF7059-E670-45F4-B422-54C40FA86390"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*","matchCriteriaId":"0D38F0BF-A728-4133-A358-D44A2F7EE6D6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*","matchCriteriaId":"EC732D08-5F7B-46D9-B154-E60C7F4F0A97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*","matchCriteriaId":"E5910A9D-F60A-409A-B486-FE66BFEBA9B9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64045","Ordinal":"1","Title":"ovpn: tcp - use cached peer pointer in ovpn_tcp_close()","CVE":"CVE-2026-64045","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64045","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\novpn: tcp - use cached peer pointer in ovpn_tcp_close()\n\novpn_tcp_close() loads the ovpn_socket via rcu_dereference_sk_user_data()\nunder rcu_read_lock(), takes a reference on sock->peer, caches the peer\npointer in a local, and drops the read lock. It then passes sock->peer\n(rather than the cached local) to ovpn_peer_del(), re-dereferencing the\novpn_socket after the RCU read section has ended.\n\nUnlike ovpn_tcp_sendmsg(), which uses the same \"load under RCU, use\nafter unlock\" pattern but is protected by lock_sock() held across the\nfunction, ovpn_tcp_close() runs without the socket lock: inet_release()\ninvokes sk_prot->close() without taking lock_sock first.\n\novpn_socket_release() can therefore complete its kref_put -> detach ->\nsynchronize_rcu -> kfree(sock) sequence concurrently, in the window\nafter ovpn_tcp_close() drops rcu_read_lock() but before it dereferences\nsock->peer. The synchronize_rcu() in ovpn_socket_release() protects\nreaders that use the dereferenced pointer inside the RCU read section,\nnot those that escape the pointer to a local and use it afterwards.\n\nA reproducer follows the pattern of commit 94560267d6c4 (\"ovpn: tcp -\ndon't deref NULL sk_socket member after tcp_close()\"): trigger a peer\nremoval (keepalive expiration or netlink OVPN_CMD_DEL_PEER) at the same\nmoment userspace closes the TCP fd. That commit fixed the detach-side\nof the same race window; this one fixes the close-side at a different\nvictim.\n\nTighten the entry block to read sock->peer exactly once into the cached\npeer local, and route all subsequent uses (the hold check, the\novpn_peer_del() call, and the prot->close() invocation) through that\nlocal. sock->peer is only ever written once in ovpn_socket_new() under\nlock_sock(), before rcu_assign_sk_user_data() publishes the ovpn_socket,\nand is never reassigned afterwards - but the previous multi-read pattern\nmade that invariant implicit rather than explicit. The same multi-read\nshape exists in ovpn_tcp_recvmsg(), ovpn_tcp_sendmsg(),\novpn_tcp_data_ready() and ovpn_tcp_write_space(); those will be cleaned\nup via a dedicated helper in a follow-up net-next series.","Type":"Description","Title":"ovpn: tcp - use cached peer pointer in ovpn_tcp_close()"}]}}}